Report for IP: 92.205.18.204

Threat LevelCRITICAL72/1002 rule types across 2 attack categories
446 incidents · 2 rule types · active attack detected · active over 3 days · 149 attacks/day · last seen 15d ago
PTR 204.18.205.92.host.secureserver.net
Org / ASN GD MASS Network
Country 🇫🇷 France
City Strasbourg, Grand Est
Timezone Europe/Paris

Attack Analysis

🇫🇷 France · Strasbourg · 21499 · Host Europe GmbH
Suricata IDS Alert
Suricata intrusion detection flagged this IP for malicious network behaviour — including port scanning, exploit attempts, botnet activity, or known attack signatures. The specific signature is shown in the report list below.
IDS: SSH Port Scan
Suricata detected automated SSH port scanning from this IP. SSH scanners map targets before launching credential brute-force attacks. This is the reconnaissance phase of a larger attack campaign.

Reports (446)

Date Severity Description
17 Jul 2026 - 00:08 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
16 Jul 2026 - 23:44 high IDS: SSH port scan — ET SCAN Potential SSH Scan
16 Jul 2026 - 23:44 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
16 Jul 2026 - 23:18 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
16 Jul 2026 - 23:18 high IDS: SSH port scan — ET SCAN Potential SSH Scan
16 Jul 2026 - 22:53 high IDS: SSH port scan — ET SCAN Potential SSH Scan
16 Jul 2026 - 22:53 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
16 Jul 2026 - 22:27 high IDS: SSH port scan — ET SCAN Potential SSH Scan
16 Jul 2026 - 22:27 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
16 Jul 2026 - 22:01 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
16 Jul 2026 - 22:01 high IDS: SSH port scan — ET SCAN Potential SSH Scan
16 Jul 2026 - 21:36 high IDS: SSH port scan — ET SCAN Potential SSH Scan
16 Jul 2026 - 21:36 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
16 Jul 2026 - 21:10 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
16 Jul 2026 - 21:10 high IDS: SSH port scan — ET SCAN Potential SSH Scan
16 Jul 2026 - 20:44 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
16 Jul 2026 - 20:44 high IDS: SSH port scan — ET SCAN Potential SSH Scan
16 Jul 2026 - 20:19 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
16 Jul 2026 - 20:19 high IDS: SSH port scan — ET SCAN Potential SSH Scan
16 Jul 2026 - 19:54 high IDS: SSH port scan — ET SCAN Potential SSH Scan